Skip to content
Banking on Bitcoin

Technology

Double Spending and 51% Attacks: What They Are and Why Bitcoin Resists Them

Double spending means spending the same coins twice. Learn how Bitcoin prevents it, what a 51% attack could and could not do, and how confirmations protect you.

By · Published

Illustration of a glowing bitcoin coin surrounded by a network of connected nodes

Key takeaways

  • Double spending means spending the same digital coins twice. Every digital cash system has to prevent it, and Bitcoin does so with a public ledger, proof of work and confirmations instead of a bank.
  • A 51% attack is when one party controls a majority of the network’s mining power. It could reorganize recent blocks, reverse its own recent payments and keep other people’s transactions out.
  • It could not take coins without the keys, change the rules that nodes enforce or create coins beyond the limit.
  • The attack is very costly on Bitcoin, though several smaller networks have suffered successful ones.
  • Each confirmation makes a payment harder to reverse, so wait for more on large amounts.

What is double spending?

Double spending is using the same digital money in two different payments. It is a problem because a digital file can be copied perfectly. A photocopied banknote will not buy lunch, but a file that says “one coin” could go to two people at once unless something stops it.

Traditional money solves this with a ledger kept by a bank. When you pay, the bank subtracts from your balance and adds to the recipient’s, and a second attempt to spend the same money is declined. Bitcoin has no bank, so the network has to do that job. The Bitcoin whitepaper names double spending as the central problem it set out to solve.

How does Bitcoin prevent double spending?

Bitcoin prevents double spending by making everyone follow one public order of transactions, in which only the first spend of a coin counts. Two mechanisms work together.

The first is checking. Every full node keeps the whole ledger and tests each new transaction against the coins still unspent, rejecting any that tries to spend something already spent. What Is a Bitcoin Node? explains what that involves.

The second is proof of work. Miners bundle transactions into blocks, and a block counts only if its hash meets the difficulty target, which takes real computing effort. Nodes follow the valid chain with the most work behind it. That turns “which payment came first?” into “which block was added to the chain?”, and rewriting that costs real work. How Does Bitcoin Work? shows the whole cycle from the user’s side.

Here is an invented example. Alice owns one coin and signs a payment of it to Bob. She also signs a second payment of the same coin back to herself and sends both out at once. Nodes keep whichever they saw first and reject the other as a conflict, though different nodes may see different ones first, so until a miner includes one in a block nobody can be sure which will win. Once a block contains Bob’s payment, the coin counts as spent in the chain and Alice’s second payment can no longer be valid. Each later block makes that outcome harder to undo.

What is a 51% attack?

A 51% attack is an attempt by one party that controls more than half of a proof-of-work network’s mining power to rewrite recent history. The number is a rule of thumb. What matters is holding a majority of the computing power, which Bitcoin Hash Rate and Mining Difficulty Explained describes.

The attacker pays a merchant, waits for the payment to confirm and collects the goods. Meanwhile, in secret, the attacker mines a rival chain that starts just before that payment and sends the same coins back to the attacker. With a majority of the mining power, that private chain will sooner or later grow longer than the public one. The attacker then publishes it. Nodes switch to the chain with more work, the merchant’s payment drops out of the chain, and the attacker can spend the coins again. This is called a chain reorganization.

A majority could also delay or block other people’s transactions by refusing to build on any block that includes them.

What can a 51% attacker not do?

A 51% attacker can rewrite recent blocks, but cannot break the rules that every node checks. That is why the attack is a threat to people who accept payments, and not a way to drain wallets.

A majority attacker couldA majority attacker could not
Reverse its own recent payments and spend those coins againTake coins from addresses it holds no keys for, because it cannot forge signatures
Block or delay other people’s transactionsChange the rules that nodes enforce, because nodes reject blocks that break them
Reorganize recent blocksCreate coins beyond the schedule, because nodes reject blocks that pay out too much

Reaching further back costs more, because every older block means redoing more work. A successful attack also tends to shake confidence in the coin, which can hurt the attacker’s own holdings. Is Bitcoin Safe? separates network security from the risks around it, and no successful attack on the core design has been recorded.

Why is a 51% attack so hard on Bitcoin?

An attack is hard because it needs enormous mining power, which is costly to acquire and run, while the payoff is limited. Four things work against an attacker.

  • Hardware. Bitcoin mining uses specialized machines, and out-computing all honest miners combined means obtaining a vast number of them.
  • Electricity. The machines must run for as long as the attack takes, and the bill arrives whether or not it succeeds.
  • Visibility. Gathering that much equipment and power is hard to do unnoticed, and a sudden change in who finds blocks shows up in public data.
  • Payoff. The attacker can only reverse its own payments, and once an attack is noticed, exchanges and merchants can demand more confirmations.

Hash rate is a rough gauge of attack cost and not a guarantee, and this article quotes no figures because they change daily.

Several smaller proof-of-work networks have suffered successful 51% attacks, in which attackers reversed transactions and double spent, and exchanges that accepted the deposits were among the victims. Those networks have far less computing power behind them, and on some of them it can be rented by the hour, which makes a majority much cheaper in absolute terms. Security comes from how much real work stands behind a chain, not from the word “blockchain”. Proof of Work vs Proof of Stake compares this model with the main alternative, which has thresholds and costs of its own.

How do confirmations protect you?

Each confirmation is another block built on top of your payment, and a reorganization has to redo all of them to reverse it. The whitepaper’s own calculation shows that an attacker with less than half the network’s power faces odds that fall exponentially with every block added on top.

StatusWhat it means for double-spending risk
UnconfirmedThe payment is only in nodes’ waiting rooms. No block has settled it, and a conflicting payment can still win.
One confirmationThe payment is in a block. Reversing it needs that block to be replaced, which is rare, and ordinary short forks can do it by chance.
Several confirmationsEach extra block makes reversal harder. Six is the traditional convention for large payments, not a guarantee.

Blocks arrive about every ten minutes on average, but at random, so the wait varies. How Long Does a Bitcoin Transaction Take? covers timing.

Do mining pools put Bitcoin at risk?

Mining pools concentrate hash power under one operator, which is why their size is watched, but the power belongs to the miners and miners can leave. Bitcoin Mining Pools Explained describes how pools work. Pools often label the blocks they find, so analysts can estimate how large each one is.

The concern has surfaced before. In 2014, one pool’s share of mining power briefly reached about half of the network, miners moved away and the pool publicly promised to stay well below that level. Even a pool with a majority could not change the rules or take coins without keys. Concentration is still a monitored concern, not a solved one.

What can an ordinary user do?

Wait for confirmations on large payments, and treat an unconfirmed payment as a promise instead of money. That one habit covers most of the practical risk.

  • Scale the wait to the amount. Many merchants accept small payments quickly and ask for more confirmations as the sum grows.
  • Be wary of “pending” screenshots. Someone who sends a picture of a payment and asks you to hand over goods first may be running a scam. Check your own wallet or a block explorer.
  • Run a node if you want to verify for yourself. It checks the rules on your own machine, though it cannot make payments confirm faster.

This article is educational. A business accepting large bitcoin payments can ask a qualified professional to help set a confirmation policy. New to Bitcoin? The Start Here path covers the basics in order.

Where to go next

Frequently asked questions

What is double spending?

Double spending means using the same digital coins in two different payments. Digital files can be copied, so any digital cash system needs a way to make sure only the first spend counts. Bitcoin uses a public ledger that every node checks, proof of work to settle the order of transactions and confirmations to show when a payment is settled.

What is a 51% attack?

A 51% attack happens when one party controls more than half of a proof-of-work network's mining power. It could reorganize recent blocks, reverse its own recent payments to spend the coins again and refuse to include other people's transactions. It could not steal coins without their keys or change the rules that nodes enforce.

Has Bitcoin ever suffered a 51% attack?

No successful 51% attack on Bitcoin has been recorded. Several smaller proof-of-work networks have been attacked, because far less mining power stands behind them. Bitcoin's size makes an attack very costly, although costly is not the same as impossible.

Can a 51% attack steal my bitcoin?

No. Spending bitcoin requires a signature from the private key, and a majority of mining power cannot forge one. The risk falls on people who accept payments from the attacker, because those payments could later be reversed.

How many confirmations are enough?

There is no single right number. One confirmation means the payment is in a block, and each further block makes it harder to reverse. Six is a long-standing convention for large payments, and smaller amounts often justify fewer.

Related articles